<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>paulmudgett.com&#187; PII</title>
	<atom:link href="http://paulmudgett.com/tag/pii/feed/" rel="self" type="application/rss+xml" />
	<link>http://paulmudgett.com</link>
	<description>Information Security &#38; Business Leadership</description>
	<lastBuildDate>Fri, 11 May 2012 16:48:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Checkbox Security Fails Again</title>
		<link>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/</link>
		<comments>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/#comments</comments>
		<pubDate>Wed, 04 Apr 2012 16:41:31 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[federal legislation]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO 27001/27002]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=453</guid>
		<description><![CDATA[Regulatory compliance is often a confusing mess.  Rattling off the alphabet of compliance can often result in dizziness, headaches, and for some, a bad case of nausea.   PCI-DSS, HIPAA, HITECH, GLB, SOX, and heck, might as well throw in some state data breach notification laws as well.  Congress doesn&#8217;t want to stop there as [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Follow-up Thought:  Facebook Credentials and Hiring Process</title>
		<link>http://paulmudgett.com/2012/04/02/follow-up-thought-facebook-credentials-and-hiring-process/</link>
		<comments>http://paulmudgett.com/2012/04/02/follow-up-thought-facebook-credentials-and-hiring-process/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 20:44:44 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Ethics]]></category>
		<category><![CDATA[disgruntled employee]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=448</guid>
		<description><![CDATA[Just a quick follow-up to my previous post &#8220;Before I hire you I&#8217;ll need the keys to your home&#8230;&#8221; I read a comment on LinkedIn that said there were no laws prohibiting employers from asking you to turn over your Facebook credentials so they can see your private information.  In my non-lawyerly view I think [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/04/02/follow-up-thought-facebook-credentials-and-hiring-process/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacker Motivation &#8211; Does it Matter?</title>
		<link>http://paulmudgett.com/2012/03/22/hacker-motivation-does-it-matter/</link>
		<comments>http://paulmudgett.com/2012/03/22/hacker-motivation-does-it-matter/#comments</comments>
		<pubDate>Thu, 22 Mar 2012 17:32:37 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[security scotoma]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=417</guid>
		<description><![CDATA[Motivation according to Dictionary.com is &#8220;the act or an instance of motivating, or providing with a reason to act in a certain way.&#8221;   While stealing data from organizations continues to be financially motivated the 2012 Verizon Data Breach Report indicated an increase in data theft as a result of hacktivism (data breaches aimed at advancing [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/03/22/hacker-motivation-does-it-matter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;We Don&#8217;t Need Security.. We Collect Taxes&#8221;</title>
		<link>http://paulmudgett.com/2012/03/21/we-dont-need-security-we-collect-taxes/</link>
		<comments>http://paulmudgett.com/2012/03/21/we-dont-need-security-we-collect-taxes/#comments</comments>
		<pubDate>Wed, 21 Mar 2012 22:04:05 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[National InfoSec]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[National Cyber Security]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[security leadership]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=412</guid>
		<description><![CDATA[If looking for a gold mine of sensitive information, the IRS appears to be the place to find it.  When individuals file their returns, the expectation is that it is well protected by the United States Government.  Unfortunately, the Government Accountability Office (GAO) has found a pattern of weakness in how the IRS protects our [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/03/21/we-dont-need-security-we-collect-taxes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More Legislation?  Hmmm.</title>
		<link>http://paulmudgett.com/2011/09/13/more-legislation-hmmm/</link>
		<comments>http://paulmudgett.com/2011/09/13/more-legislation-hmmm/#comments</comments>
		<pubDate>Tue, 13 Sep 2011 20:44:05 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[federal legislation]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=376</guid>
		<description><![CDATA[Senator Richard Blumenthal, D-Conn, introduced new legislation aimed to prevent data breaches.   The proposed legislation includes federal requirements for customer notification in the event of a breach (something most States have been requiring for years) and requiring companies to provide two years of credit monitoring service.  There are fines and program requirements for regularly testing [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2011/09/13/more-legislation-hmmm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do you know where your data is?</title>
		<link>http://paulmudgett.com/2010/12/03/do-you-know-where-your-data-is/</link>
		<comments>http://paulmudgett.com/2010/12/03/do-you-know-where-your-data-is/#comments</comments>
		<pubDate>Fri, 03 Dec 2010 19:33:58 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[insider threat]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=274</guid>
		<description><![CDATA[Where is your sensitive information? Many times the answer I hear is&#8230; &#8220;it&#8217;s stored in our database&#8221; but that unfortunately is only a partial answer.   If you look at the business process surrounding access to information, you may be surprised at where sensitive information ends up.   Have you considered: Printed documents &#8211; Hard copy printouts [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/12/03/do-you-know-where-your-data-is/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NJ Supreme Court impacts privacy expectation</title>
		<link>http://paulmudgett.com/2010/04/05/nj-supreme-court-impacts-privacy-expectation/</link>
		<comments>http://paulmudgett.com/2010/04/05/nj-supreme-court-impacts-privacy-expectation/#comments</comments>
		<pubDate>Mon, 05 Apr 2010 17:58:22 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[disgruntled employee]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[insider threat]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=191</guid>
		<description><![CDATA[The New Jersey Supreme Court recently ruled that a company shouldn&#8217;t have read an ex-staffer&#8217;s private e-mails even though they were sent from her employer&#8217;s computer.    NorthJersey.com article. Interesting ruling which will certainly change some thoughts as to personal use of work computers.  While I&#8217;m a proponent of privacy rights, I&#8217;m torn on this particular [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/04/05/nj-supreme-court-impacts-privacy-expectation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2010 Information Security Predictions</title>
		<link>http://paulmudgett.com/2010/01/03/2010-information-security-predictions/</link>
		<comments>http://paulmudgett.com/2010/01/03/2010-information-security-predictions/#comments</comments>
		<pubDate>Sun, 03 Jan 2010 19:22:40 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Awareness and Education]]></category>
		<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National InfoSec]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[National Cyber Security]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[security vision]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=120</guid>
		<description><![CDATA[I may as well get on the 2010 prediction bandwagon. 1.  With the rush to get into the &#8220;cloud&#8221; businesses will sacrifice security for the promise of efficiencies.  Attacks will be focused on the applications placed in the cloud, not necessarily the underlying OS infrastructure.  I predict there will be a large compromise of information [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/01/03/2010-information-security-predictions/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>House passes Data Breach legislation&#8230; jury still out</title>
		<link>http://paulmudgett.com/2009/12/14/house-passes-data-breach-legislation-jury-still-out/</link>
		<comments>http://paulmudgett.com/2009/12/14/house-passes-data-breach-legislation-jury-still-out/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 18:35:56 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[National Cyber Security]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=109</guid>
		<description><![CDATA[The U.S. House of Representatives has passed HR 2221, the Data Accountability and Trust Act.  This sets nationwide breach notification requirements that trump the patchwork of State laws that have been in effect with California leading the way in 2002.   The passage was written about in a Federal Computer Week article &#8220;House passes bill to [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/12/14/house-passes-data-breach-legislation-jury-still-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Learning From Someone Else&#8217;s Breach</title>
		<link>http://paulmudgett.com/2009/11/20/learning-from-someone-elses-breach/</link>
		<comments>http://paulmudgett.com/2009/11/20/learning-from-someone-elses-breach/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 19:37:07 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=100</guid>
		<description><![CDATA[A subsidiary of manged health care provider Health Net Inc, just reported the loss of personal information for 1.5 million customers that occurred six months ago according to a ComputerWorld article.  Without knowing all the details of the situation, I can only speculate as to some of the security controls and thoughts of the Health [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/11/20/learning-from-someone-elses-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

